2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-28856
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

CVE-2020-35853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the crafted payload.

CVE-2020-10667
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version.

CVE-2020-20943
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.

CVE-2020-26129
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

CVE-2020-20138
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.

CVE-2020-25562
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent.

CVE-2020-18714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.

CVE-2020-28184
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.

CVE-2020-18713
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php

CVE-2020-11438
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

LibreHealth EMR v2.0.0 is affected by systemic CSRF.

CVE-2020-12643
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.

CVE-2020-25990
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-25834
ArcSight Logger Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2020-28956
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.

CVE-2020-11946
Software Genérico Web
N/A
UNKNOWN
EPSS
67.0%
2020 1 PoC

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

CVE-2020-20946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.

CVE-2020-19282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

CVE-2020-2322
Jenkins Chaos Monkey Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.